Intel

AIKIDO-2026-10269

ai is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 2, 2026

50

Medium Risk

This Affects:

JSai
0.0.1 - 6.0.83
Fixed in 6.0.84
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an unbounded download denial-of-service (DoS) issue where large or uncontrolled downloads can exhaust resources and potentially crash or hang applications. The underlying problem occurs when the SDK does not properly limit the size of downloads, allowing adversarial or unexpectedly large content to be fetched without safeguards. This can result in excessive memory or CPU usage and degraded availability for applications using the AI toolkit. The vulnerability is fixed by introducing bounds and safeguards on download operations to prevent unbounded resource consumption during file retrieval and processing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ai is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 6.0.83.

How to fix this

Upgrade the ai library to the patch version.